Thursday, 2011-09-01

*** Joins: paulf (7346ad2a@gateway/web/freenode/ip.115.70.173.42)00:22
paulfhi00:23
*** Quits: paulf (7346ad2a@gateway/web/freenode/ip.115.70.173.42) (Client Quit)00:23
*** Quits: kirillka (~Miranda@75-193-55-95.baltnet.ru) (Quit: kirillka)00:40
*** Joins: kirillka (~Miranda@195.242.142.17)01:02
*** Quits: brucelee (~adsfasdf@c-67-160-201-8.hsd1.ca.comcast.net) (Read error: Connection reset by peer)02:20
*** Joins: brucelee (~adsfasdf@c-67-160-201-8.hsd1.ca.comcast.net)02:21
*** Joins: soustruh (~Miranda@ip-86-49-121-75.net.upcbroadband.cz)02:31
*** Quits: siebrand (~siebrand@5353A6DC.cm-6-4c.dynamic.ziggo.nl) (Quit: siebrand)02:38
*** Joins: dregad (~dregad@wwwgate1.merck.de)03:11
*** Joins: siebrand (~siebrand@188.200.34.66)03:16
*** Joins: Arvidius (~Arvidius@188.201.221.57)03:26
Arvidiushey03:27
ArvidiusI have a question regarding mantis03:27
ArvidiusI installed it on my webserver and I really like it but I'm missing 1 feature03:27
Arvidiusis it possible to set a deadline for every bug that is added?03:28
Arvidiusan to remember the owner of the bug if the deadline is getting close?03:28
dregadArvidius: setting deadline --> yes03:33
dregadreminder - not sure, I don't use this feature03:33
*** Quits: Arvidius (~Arvidius@188.201.221.57) (Ping timeout: 264 seconds)03:33
*** Joins: Arvidius (~Arvidius@188.201.221.57)03:36
dregadcheck $g_due_date_update_threshold and $g_due_date_view_threshold03:36
ArvidiusI am sorry, I do not really understand?03:37
dregadthese are options you can set in config_inc.php03:38
dregadby default the threshold is NOBODY meaning the feature is disabled03:38
Arvidiusok, and with those options set I can use the feature I am looking for?03:39
dregadit enables a due-date field which I think is what you need03:39
dregaddoes not handle the notification though - don't think that Mantis can do that, you might have to setup a custom cron job03:40
Arvidiusthanks, I will try that :-)03:40
*** Quits: Arvidius (~Arvidius@188.201.221.57) ()03:43
*** Quits: Cesare (~Adium@creati59.lnk.telstra.net) (Quit: Leaving.)03:55
*** Joins: fredcooke (~fred@131.2.221.87.dynamic.jazztel.es)04:22
*** Joins: asm89 (~asm89@unaffiliated/asm89)04:27
*** Joins: paul__ (52c6fa03@gateway/web/freenode/ip.82.198.250.3)04:28
paul__moo04:28
dhx1paul__: hey04:30
paul__lo04:30
paul__I ran appscan over my codebase last week, and over 1.2.7 yesterday - i.e. http://www-01.ibm.com/software/awdtools/appscan/04:31
dhx1paul__: any results?04:35
paul__a bunch of invalid stuff, and some stuff that needs fixing basically04:38
paul__i'm at work atm, that's at home04:38
dhx1XSS?04:40
paul__ya04:40
dhx1hmmm04:40
dhx1can you email me a copy when you get home?04:40
dhx1I can't wait to kill off 1.2.x...04:40
dhx1and for more browsers to support X-Content-Security-Policy... and then eventually, a version of MantisBT that has proper layout/content separation04:41
dregadhi04:48
dregadyou guys seen this ? https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_mantisbt.html04:48
paul__yea04:50
paul__not seen what though04:50
paul__wouldn't be surprised if i've already found the bugs with the scans i've done though04:50
dhx1why are security firms so useless at talking to open source projects?04:50
dregadaccording to their policy, they would have sent a detailed e-mail04:50
dregadbut question is, to whom...04:51
dhx1maybe Victor04:51
dhx1it's happened before04:51
*** Quits: asm89 (~asm89@unaffiliated/asm89) (Quit: reboot)04:51
dregadFunny, that company's based in Geneva, less than 1 km away from my office04:52
dhx1LFI is bad... if it's true04:52
dhx1sounds similar to http://www.mantisbt.org/bugs/view.php?id=1260704:52
dregadLFI ? which one do you mean http://en.wikipedia.org/wiki/LFI04:53
*** Joins: asm89 (~asm89@unaffiliated/asm89)04:53
dhx1dregad: http://en.wikipedia.org/wiki/Local_File_Inclusion04:54
dhx1oh nm, htbridge posted a bug04:55
dregadjust saw it04:56
dhx1oooh yeah that's bad04:57
dhx1or maybe not (on nginx) because you can't traverse upwards from a file04:58
asm89what is that appscan? sounds like a nice tool04:58
dhx1hmmm why is document.cookie working on mantisbt.org? HttpOnly is meant to be turned on :grrr:05:00
dhx1oh, it's only supported for PHP > 5.2.005:01
paul__1/2+others i've already found + fixed05:08
asm89paul__: is that ibm tool a tool you use @work?05:11
dhx1paul__: I'll beat you to it :)05:13
dregaddhx1: especially if paul__ forgets to push ::grin::05:16
dhx1haha05:16
*** Quits: CIA-33 (~CIA@cia.atheme.org) (*.net *.split)05:40
*** Joins: CIA-33 (~CIA@cia.atheme.org)05:42
paul__asm89: not exactly ;p05:59
paul__but a tool I can get access to06:00
asm89ah nice :)06:01
paul__I plan to push the fixes i've found from said tool and send an email to list within next 12 hours06:03
paul__once those are pushed will take a look to see if those fixes have already covered the issues htbridge report06:04
dregadpaul__ coordinate your work with dhx as I'm sure is already on the htbridge report...06:15
paul__well, as I say, I think some of the htbridge issues i've already identified06:16
paul__I was planning on posting an advisory type of mail about the issues that appscan threw up once i'd checked them all out06:16
dhx1I'll have those htbridge vulnerabilities patched up shortly06:21
paul__dhx1: please dont06:21
dhx1and then I'll wait for yours (if they're different)06:21
paul__as I've already fixed them06:21
dhx1I'm doing them right :)06:21
paul__I think06:21
GitHub25[mantisbt] davidhicks pushed 1 new commit to master: http://git.io/4ShkWg07:29
GitHub25[mantisbt/master] Fix #13282, #13283: bug_actiongroup_ext_page.php LFI and XSS - David Hicks07:29
GitHub141[mantisbt] davidhicks pushed 1 new commit to master-1.2.x: http://git.io/guFs7Q07:29
GitHub141[mantisbt/master-1.2.x] Fix #13282, #13283: bug_actiongroup_ext_page.php LFI and XSS - David Hicks07:29
*** Joins: tsnfoo (~fulekia@ws-imac27.test.denison.edu)08:52
*** Joins: daryn (~daryn@h158.249.190.173.static.ip.windstream.net)09:00
*** Quits: kirillka (~Miranda@195.242.142.17) (Quit: kirillka)09:59
*** Quits: paul__ (52c6fa03@gateway/web/freenode/ip.82.198.250.3) (Quit: Page closed)11:15
*** Quits: asm89 (~asm89@unaffiliated/asm89) (Quit: bye)11:19
*** Quits: soustruh (~Miranda@ip-86-49-121-75.net.upcbroadband.cz) (Quit: visit http://wormscesky.cz)12:39
*** Quits: siebrand (~siebrand@188.200.34.66) (Quit: siebrand)13:35
*** Joins: Phileas1 (~Phileas1@56.110.63.81.cust.bluewin.ch)14:23
*** Joins: JonMarkGo (~Jon@ool-18bfe16f.dyn.optonline.net)14:50
*** Quits: Phileas1 (~Phileas1@56.110.63.81.cust.bluewin.ch) (Quit: ChatZilla 0.9.87 [Firefox 3.6.20/20110803131630])15:46
*** Joins: siebrand (~siebrand@5353A6DC.cm-6-4c.dynamic.ziggo.nl)16:47
*** Joins: soustruh (~Miranda@ip-86-49-121-75.net.upcbroadband.cz)17:18
*** Parts: fredcooke (~fred@131.2.221.87.dynamic.jazztel.es) ("ISON zyp shaggymane dcramer `CHR1S1 TekniQue `CHR1S seank_ gurov rxKaffee kb1gtt1 obi-lan Lev8n TekniQue_ tomi_ge seank-efi Milosch hena pinztrek obi-lan_ jr- pieloverr djandruczyk gufi BassGuy sry_not4sale Evie johntramp Quan-Time Evie|shell Evie^2 piimae diy")17:19
*** Quits: daryn (~daryn@h158.249.190.173.static.ip.windstream.net) (Quit: Ex-Chat)17:28
*** Quits: soustruh (~Miranda@ip-86-49-121-75.net.upcbroadband.cz) (Quit: visit http://wormscesky.cz)18:40
*** Joins: Cesare (~Adium@creati59.lnk.telstra.net)19:21
*** Quits: micahg (~micahg@ubuntu/member/micahg) (Read error: Connection reset by peer)19:56
*** Joins: micahg (~micahg@ubuntu/member/micahg)19:57
*** Quits: scribe9343423 (~scribe934@static.96.23.63.178.clients.your-server.de) (Remote host closed the connection)20:00
*** Joins: scribe9343423 (~scribe934@static.96.23.63.178.clients.your-server.de)20:00
*** Quits: micahg (~micahg@ubuntu/member/micahg) (Read error: Operation timed out)20:55
*** Joins: micahg (~micahg@ubuntu/member/micahg)20:57

Generated by irclog2html.py 2.9.2 by Marius Gedminas - find it at mg.pov.lt!